
Web Push Notifications – Webpushr Security & Risk Analysis
wordpress.org/plugins/webpushr-web-push-notificationsFastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Is Web Push Notifications – Webpushr Safe to Use in 2026?
Generally Safe
Score 92/100Web Push Notifications – Webpushr has a strong security track record. Known vulnerabilities have been patched promptly.
The webpushr-web-push-notifications plugin version 4.39.0 exhibits a mixed security posture. While it demonstrates some good practices like the use of prepared statements for a majority of its SQL queries and a decent number of nonce and capability checks, significant concerns arise from its entry points and historical vulnerability patterns. The presence of an unprotected AJAX handler presents a direct attack vector, and the taint analysis revealed a flow with an unsanitized path, suggesting potential for vulnerabilities if not handled carefully. The plugin's history of four known CVEs, including high and medium severity issues like Cross-Site Scripting, Missing Authorization, and Exposure of Sensitive Information, indicates a recurring struggle with robust security implementation. The commonality of these vulnerability types suggests systemic issues in input validation, authorization, and output sanitization that need persistent attention. While the current version has no unpatched vulnerabilities, the past pattern and the static analysis findings necessitate vigilance. Overall, the plugin has strengths in areas like SQL handling, but the unprotected entry points and historical issues warrant a cautious approach to its deployment.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized paths
- High severity past vulnerabilities (2 high)
- Medium severity past vulnerabilities (2 medium)
- Output escaping is not consistently proper (54%)
Web Push Notifications – Webpushr Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Webpushr <= 4.38.0 - Unauthenticated Information Exposure
Webpushr <= 4.35.0 - Reflected Cross-Site Scripting
Webpushr <= 4.34.0 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting
Webpushr <= 4.34.0 - Cross-Site Request Forgery to Local File Inclusion via menu
Web Push Notifications – Webpushr Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Web Push Notifications – Webpushr Attack Surface
AJAX Handlers 1
WordPress Hooks 35
Scheduled Events 1
Maintenance & Trust
Web Push Notifications – Webpushr Maintenance & Trust
Maintenance Signals
Community Trust
Web Push Notifications – Webpushr Alternatives
Push Magnet
push-magnet-web-push-notifications
World's best tool for Web Push Notifications. Instantly add it to any website and engage with your visitors.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
iZooto – Web Push Notifications
izooto-web-push
Engage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
Web Push Notifications – Webpushr Developer Profile
1 plugin · 10K total installs
How We Detect Web Push Notifications – Webpushr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webpushr-web-push-notifications/css/webpushr_admin.min.css/wp-content/plugins/webpushr-web-push-notifications/js/webpushr_admin.min.jshttps://cdn.webpushr.com/app.min.jshttps://cdn.webpushr.com/sw-server.min.jswebpushr-web-push-notifications/css/webpushr_admin.min.css?ver=4.11.0webpushr-web-push-notifications/js/webpushr_admin.min.js?ver=1.4HTML / DOM Fingerprints
webpushr